nvme-gen-tls-key(1)
===================

NAME
----
nvme-gen-tls-key - Generate a NVMe TLS PSK (deprecated)

SYNOPSIS
--------
[verse]
'nvme' [<global-options>] 'gen-tls-key' [--keyring=<name> | -k <name>]
			[--keytype=<type> | -t <type>]
			[--hostnqn=<nqn> | -n <nqn>]
			[--subsysnqn=<nqn> | -c <nqn>]
			[--hmac=<hmac-id> | -m <hmac-id>]
			[--identity=<id-vers> | -I <id-vers>]
			[--secret=<secret> | -s <secret>]
			[--insert | -i]
			[--compat | -C]
			[--keyfile=<keyfile> | -f <keyfile>]

DESCRIPTION
-----------
Deprecated alias for linknvme:nvme-keys-gen-tls-psk[1], kept for scripts
written against nvme-cli versions older than 3.0, with three differences
from nvme-cli 2.x:

* '--insert'/'-i' reports 'Inserted TLS PSK <serial>' where 2.x said
  'Inserted TLS key <serial>'. A script matching the old wording needs
  updating.

* A '--secret' with an odd number of hexadecimal characters is rejected.
  2.x padded the trailing character with a zero and emitted a secret that
  was never given, the same behaviour
  linknvme:nvme-gen-dhchap-key[1] had.

* The diagnostics that validate '--secret' go to stdout, where 2.x put
  them on stderr. Most of them accompany a non-zero exit, but
  'Skipping excess secret bytes' does not: an over-long '--secret'
  still exits 0, with the warning sitting on stdout ahead of the key,
  so a script reading the key off stdout gets the warning instead.

New scripts should use 'nvme keys gen-tls-psk' instead. This alias prints a
deprecation warning on stderr and may be removed in a future release.

See linknvme:nvme-keys-gen-tls-psk[1] for the full option reference.

include::global-options.txt[]

EXAMPLES
--------
No Examples

NVME
----
Part of the nvme-user suite

SEE ALSO
--------
linknvme:nvme-keys-gen-tls-psk[1]
